CVE-2026-104971: Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEndpoint Missing Authorization
Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who can exploit these issues?
An authenticated Plane user can exploit the affected asset and workspace-view endpoints. For the asset issues, the user does not need to be a member of the workspace containing the targeted assets.
What access could an attacker gain or abuse?
An attacker could duplicate a file asset from another workspace, and could read, create, modify, or delete assets in workspaces where they are not a member. They may also read workspace-view data through the affected retrieve action.
Are unauthenticated deployments affected?
The described attack paths require an authenticated user with low privileges; no user interaction is required. The provided information does not identify any configuration prerequisite beyond running a Plane version prior to 1.4.0.
What is the remediation?
Upgrade Plane to version 1.4.0, which fixes the reported authorization flaws. The provided information does not specify a workaround if upgrading cannot be performed immediately.